PatchSiren

Entity Browser Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Entity Browser Project CVE published 2026-09-02

CVE-2026-18986

A Cross-site Scripting (XSS) vulnerability exists in Entity Browser versions from 0.0.0 to 2.16.0 due to improper neutralization of input during web page generation. This issue allows stored XSS attacks. The vulnerability impacts Drupal installations using Entity Browser, allowing attackers to inject malicious scripts. Defenders should assess exposure and prioritize patching or mitigation to prevent poten [truncated]